Audit and Compliance View
Every operator action, alert, override, and model version is recorded in an attributable, tamper-evident timeline that supports regulators, reviews, and trust.
An accountable record of everything that happened
A fusion plant handling tritium (breeder) and operating under a nuclear-adjacent regulatory framework must be able to show, after the fact, exactly what happened and who did what. The audit view is the operator-facing window into that record: a searchable, attributable, tamper-evident timeline of alerts, acknowledgements, overrides, mode changes, escalations, and the model versions in effect at each moment.
What is recorded
- Every alert: when it fired, its confidence, its recommended action
- Every operator action: who, what, when, and the reason if it was an override
- Model provenance: which model version produced each acted-upon estimate
- Escalations: who was paged, when acknowledged, what was decided
- Mode and automation-level changes, with the authorizing identity
- Shelved alarms and the justification for shelving
The record is generated automatically from the live systems, not curated by hand, so it cannot be edited by hand into a cleaner story — and it is tamper-evident so any alteration is detectable. Attribution ties every action to an identity, which is why mobile and console actions alike carry strong authentication: an unattributable action would be a hole in the record.
From audit to improvement
The audit record is not only for compliance; it is the substrate for learning. Overrides recorded with reasons show where humans and the AI disagreed, feeding the L0 retraining loop. Escalation timings show where response paths were slow. Alarm statistics show where rationalization needs another pass. In this sense the honest record closes the loop between operation and the models that support it.
The audit view shares its raw material with incident replay and shift handover, and it is the accountability backstop behind trust and override. Handling of any sensitive content follows the plant's security and access rules; the audit surface enforces least-privilege access just as the mobile surface does.